PDA

View Full Version : Changing My Homepage (W2K)



AtariFan
01-27-2004, 02:12 PM
Some how my default homepage, when I open Internet Explorer, has been changed. I am unable to change it back. Saving a new homepage in internet options does not help either. I have already tried running adaware and spybot. Please help!

unknown634
01-27-2004, 02:18 PM
I bet you've been hijacked. Try psoting a hijackthis scan to see if we can't find the problem...
Post a Hijack log by doing this:
VBProg (http://tomcoyote.org/hjt>Download</a>,)

AtariFan
01-27-2004, 02:41 PM
Here it goes...
Logfile of HijackThis v1.97.7
Scan saved at 2:39:47 PM, on 1/27/2004
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\WINNT\Explorer.exe
C:\Program Files\2Wire\Gateway\2PortalMon.exe
C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04. exe
C:\Program Files\Navnt\navapw32.exe
C:\PROGRA~1\YAHOO!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.windowws.cc/sp.htm?id=562
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.windowws.cc/sp.htm?id=562
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.windowws.cc/sp.htm?id=562
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://awebfind.biz/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://awebfind.biz/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.windowws.cc/sp.htm?id=562
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://awebfind.biz/sp.htm
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://awebfind.biz/sp.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://vcfwqg.t.muxa.cc/h.php?aid=359 (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vcfwqg.t.muxa.cc/s.php?aid=359 (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vcfwqg.t.muxa.cc/s.php?aid=359 (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://awebfind.biz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://awebfind.biz/sp.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://awebfind.biz/sp.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vcfwqg.t.muxa.cc/s.php?aid=359 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/sbcydsl/defaults/su/*http://www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\Program Files\Yahoo!\Common\ycomp5,0,8,0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,0,8,0.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\Gateway\2PortalMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04. exe
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\Navnt\defalert.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [9wwzjz6bdu] C:\WINNT\0vg4g1wj9n.exe
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O9 - Extra button: Yahoo! Login (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Login (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38008.3175231482
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://download.yahoo.com/dl/installs/ymail/ymmapi.dll

I hope I did that correctly. Thanks

unknown634
01-27-2004, 05:34 PM
Yep worked good.

Have Hijack this fix these:

O4 - HKCU\..\Run: [9wwzjz6bdu] C:\WINNT\0vg4g1wj9n.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://awebfind.biz/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://awebfind.biz/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.windowws.cc/sp.htm?id=562
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://awebfind.biz/sp.htm
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://awebfind.biz/sp.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://vcfwqg.t.muxa.cc/h.php?aid=359 (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vcfwqg.t.muxa.cc/s.php?aid=359 (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vcfwqg.t.muxa.cc/s.php?aid=359 (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://awebfind.biz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://awebfind.biz/sp.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://awebfind.biz/sp.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://vcfwqg.t.muxa.cc/s.php?aid=359 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.windowws.cc/sp.htm?id=562
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.windowws.cc/sp.htm?id=562
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.windowws.cc/sp.htm?id=562

Reboot then,
C:\WINNT\0vg4g1wj9n.exe &lt;--Go delete this file

See if this fixes it for you.
-Unknown

Visit my site of progs [small for now]
<a target="_blank" href=http://www-personal.umd.umich.edu/~amalenfa>VBProg</a>

AtariFan
01-27-2004, 09:33 PM
Awesome! Thank you. It seems to have removed the unwanted homepage from my system. I have a few questions if you have the time. First, Is this my registry? If not, what is it, and what is my registry? (A short answer would be just fine.) How did you know which items should not be there? Now that my "registry" is clean, can I back it up or copy it so that I know what items are forign next time? Also, What was the deal with rebooting and deleting the last exe file? Why was that nessisary? My bonus question is, is there some way I could enter an item in my registry so that I could set my own "default" homepage? Any info is appreciated, I'm just learning... Anyway, thanks for all your help!

unknown634
01-28-2004, 09:34 AM
Registry:
Yes, it did fix some registry stuff and backed it up to the same place you ran Hijack this from (you can open then in Notepad and copy their info into one text file)
Long story short, the Registry is a large database that saves settings of programs and even hardware settings. *ALWAYS* exercise caution in the registry, as it can screw things up (I know, I did something to make Explorer crash randomly.) Back it up before making a change!
To access, go Start Menu &gt; Run &gt; regedit
Hives:
HKEY_CURRENT_USER [HKCU] (Settings applying only to the current user)
HKEY_LOCAL_MACHINE [HKLM] (Settings applying to all users)
HKEY_CLASSES_ROOT [HKCU] (Mostly file type associations and Class IDs)

Keys: The "folder" type items
Values: Various types of data (Strings, Expanded Strings, Binary and DWORD are examples of types)
(If anyone knows of a page that describes it better than I can, please post a link!)

That EXE file at the end was running at startup and was probably spyware or malware, which most likely kept resetting your home page at Windows startup. It's startup key was the first reg entry I listed that Hijack fix, and by deleting that file ensuring it can't do anything more, with the reboot making sure its out of memory for good. Being it had a really off the wall name like that gave away it malicious intent. There's some viruses that hide with system like names in system folders:
RUNDLL16.EXE, CMD32.EXE, SYSTEM32.EXE are just some examples of viruses in disguise.
<a target="_blank" href=http://www.liutilities.com/products/wintaskspro/processlibrary>Good process list</a> They have them categorized by malware/spyware, system processes and legit stuff you might have.

As for changing the default home page at startup...
Copy and paste this into Notepad:

<font color=red>
dim WinReg
Const RegKey = "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page"
Set WinReg = CreateObject("Wscript.Shell")
WinReg.RegWrite RegKey, "&lt;insert your Home page here&gt;"
</font color=red>
Insert you home page where noted.

Save this to C:\Documents and Settings\All Users\Start Menu\Programs\Startup

as any name with a .vbs after it.

I hope I hit all your questions...let me know if you want any more info...
Unknown

Visit my site of progs [small for now]
<a target="_blank" href=http://www-personal.umd.umich.edu/~amalenfa>VBProg</a>